
Phantom Security Group provides offensive security tooling for red teams, offering EvadeX for automated, signature-free payload generation and ApeX C2, a Stage 0 command and control framework. The platform focuses on evading mainstream EDRs through continuous updates and backed memory execution, with EvadeX featuring a browser-based interface and API for workflow integration.
Funding
Funding not disclosed
Founders
Product
Problem
Red teams and penetration testers often find that mainstream offensive security tools are easily detected by modern endpoint detection and response (EDR) systems. Existing payload generators and command and control (C2) frameworks frequently rely on predictable techniques, such as executing shellcode from unbacked memory, which triggers common detection signatures and compromises the success of security assessments.
Solution
Phantom Security Group addresses this by delivering offensive security tooling designed for operational effectiveness against current defenses. The company offers EvadeX, an automated payload framework that generates signature-free binaries from user-supplied shellcode, and ApeX C2, a Stage 0 command and control framework that executes from backed memory to avoid standard detections. Both products are built with evasion as a core principle, ensuring they remain effective against mainstream EDR solutions. The platform is trusted in production by red teams, providing continuous updates to keep pace with evolving security controls.
Target Audience
The primary customers are professional red teams and penetration testers who require reliable, evasive tooling for authorized security assessments and need to bypass modern endpoint defenses.
Features
- EvadeX provides automated payload creation directly in the browser, simplifying the generation of custom loaders.
- Continuous evasion updates ensure the tools remain effective against current EDR signatures and detection techniques.
- ApeX C2 uses Stage 0 loader tradecraft and backed memory execution to bypass a common class of C2 detections.
- The platform offers a first-class API for EvadeX, enabling integration into existing red team workflows and automation pipelines.